Intel

AIKIDO-2026-67396

cowlib is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or ThrottlingCVE-2026-59248 Published Jul 29, 2026

87

High Risk

This Affects:

ELIXIRcowlib
2.0.0 - 2.18.0
Fixed in 2.19.0
Are you affected? Scan for Free

TL;DR

cowlib contains an uncontrolled resource consumption vulnerability in its HPACK and QPACK integer decoder. An unauthenticated attacker can send specially crafted HTTP/2 or HTTP/3 header fields containing excessively long prefixed integers, causing excessive memory allocation and garbage collection due to inefficient bignum processing. Repeated requests can exhaust server memory and lead to a denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cowlib is vulnerable to Allocation of Resources Without Limits or Throttling in versions 2.0.0 - 2.18.0.

How to fix this

Upgrade the cowlib library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform